Wiki Web Help 'getpage.php' SQL Injection Vulnerability
BID:41344
Info
Wiki Web Help 'getpage.php' SQL Injection Vulnerability
| Bugtraq ID: | 41344 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2010 12:00AM |
| Updated: | Jul 05 2010 11:07PM |
| Credit: | ADEO Security |
| Vulnerable: |
Richard Bondi Wiki Web Help 0.2.8 Richard Bondi Wiki Web Help 0.2.7 Richard Bondi Wiki Web Help 0.2.6 Richard Bondi Wiki Web Help 0.2.5 Richard Bondi Wiki Web Help 0.2.4 Richard Bondi Wiki Web Help 0.2.3 Richard Bondi Wiki Web Help 0.2.2 Richard Bondi Wiki Web Help 0.2.1 Richard Bondi Wiki Web Help 0.2 |
| Not Vulnerable: |
Richard Bondi Wiki Web Help 0.2.10 |
Discussion
Wiki Web Help 'getpage.php' SQL Injection Vulnerability
Wiki Web Help is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Wiki Web Help 0.2.8 is vulnerable; other versions may also be affected.
Wiki Web Help is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Wiki Web Help 0.2.8 is vulnerable; other versions may also be affected.
Exploit / POC
Wiki Web Help 'getpage.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/handlers/getpage.php?id=9999999+UNION+SELECT+1,CONCAT_WS(0x3a,user_name,password),3,4,5,6,7+FROM+user+LIMIT+1
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/handlers/getpage.php?id=9999999+UNION+SELECT+1,CONCAT_WS(0x3a,user_name,password),3,4,5,6,7+FROM+user+LIMIT+1
Solution / Fix
Wiki Web Help 'getpage.php' SQL Injection Vulnerability
Solution:
Updates are available; please see the references for more information.
Richard Bondi Wiki Web Help 0.2
Richard Bondi Wiki Web Help 0.2.1
Richard Bondi Wiki Web Help 0.2.2
Richard Bondi Wiki Web Help 0.2.3
Richard Bondi Wiki Web Help 0.2.4
Richard Bondi Wiki Web Help 0.2.5
Richard Bondi Wiki Web Help 0.2.6
Richard Bondi Wiki Web Help 0.2.7
Richard Bondi Wiki Web Help 0.2.8
Solution:
Updates are available; please see the references for more information.
Richard Bondi Wiki Web Help 0.2
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.1
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.2
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.3
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.4
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.5
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.6
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.7
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
Richard Bondi Wiki Web Help 0.2.8
-
Richard Bondi wwh-0.2.10.zip
http://wikiwebhelp.org/release/wwh-0.2.10.zip
References
Wiki Web Help 'getpage.php' SQL Injection Vulnerability
References:
References:
- Wiki Web Help Homepage (Richard Bondi)
- Wiki Web Help Project Page (Wiki Web Help)